EDBT 2026 Demo / reviewers in the wild / expert
Hannes Salin
dblp:282/6447
· DBLP profile ↗
22ranked-venue papers
13as first author
21since 2021 · last 2025
0000-0001-6327-3565ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 7 first-author · 13 since 2021Software engineering, systems software and programming languages · 6 · 6 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Building a Decision Landscape Model for Software Development: From Empirical Insights to Formal Theory
Hannes Salin |
ICSOFT | 1 |
| 2025 | A Comparative Analysis of Anonymous and Non-Anonymous Authorization Architectures for IoT Environments in Cooperative Intelligent Transport Systems
Hannes Salin |
IoTBDS | 1 |
| 2024 | Small Mistakes with Big Impacts: A Study on Secure Coding Practices in Java Open Source Projects
Hannes Salin |
CRiSIS | 1 |
| 2024 | The Game of One More Idea: Gamification of Managerial Group Decision-Making in Software Engineering
Hannes Salin |
ICSOFT | 1 |
| 2024 | Distributed Data Possession - Blockchain Based ScalabilityabstractProvable Data Possession (PDP) mechanisms allows for efficient verification of data integrity in remote storage platforms. In this paper, we show an efficient way to use a secure PDP scheme for cloud storage with blockchain technology. In our system, verification nodes in the blockchain network challenge data centers through distributed PDP transactions. We show that our method is effective, which is confirmed by experimental results. Bartlomiej Dzikowski, Lukasz Krzywiecki, Ksawery Mozdzynski, Karol Niczyj, Hannes Salin |
TrustCom | 5 |
| 2024 | Privacy-Preserving Real-Time Gesture Recognition using Cloud-Trained Neural NetworksabstractThis paper presents a novel approach to privacy-preserving gesture recognition using a remotely trained neural network. Our method ensures the protection of sensitive user data from potential threats, thereby mitigating concerns about data privacy and security. By utilizing encryption techniques, we enable organizations to train complex machine learning models on large-scale datasets without compromising data integrity. We demonstrate the feasibility of this approach through the implementation of proposed models for gesture classification, which achieved high accuracy in both encrypted and plain modes. Our results show that these models are suitable for embedded devices, making them a viable option for commercial or industrial applications such as smart car navigation systems. Kewin Ignasiak, Wojciech Kowalczyk, Lukasz Krzywiecki, Mateusz Nasewicz, Hannes Salin, Marcin Zawada |
TrustCom | 5 |
| 2023 | Thrifty Guardians: Overcoming the Challenges of Establishing Security Champions on a Limited BudgetabstractIn this case study conducted over a six-months period where a Security Champions team was established, and an additional month for the remaining data collection and analysis, we explore the challenges and strategies in forming and sustaining a Security Champion team in a mid-size software engineering organization, given a very limited budget. Our research questions focus on identifying the main challenges and key success strategies when establishing such a team, to enable security awareness, competence and focus, with cost-efficient approaches. The chosen research methodology consisted of an exploratory case study, involving 11 Security Champion team members and two key stakeholders. A mixed-method approach was used, collecting data via semi-structured interviews and an online self-assessment survey, further processed with structural coding to identify key success factors and challenges. Our study shows that it is possible to establish a Security Champion team on a strictly limited budget, given the following identified key success factors: the team leader possesses prior experience with the concept, the team have short but frequent meetings, there is buy-in from management, team members, and other security organizations, and there are enough situations where the Champions can apply their skills. However, challenges persist, including lack of clear goals, unclear prioritization, lack of internal support, lack of buy-in from other security organizations and efficient ways to utilize the Champions’ skills within their teams. This study contributes by identifying key success factors and challenges to mitigate, for organizations looking to establish a Security Champion team with limited resources. Hannes Salin |
SEAA | 1 |
| 2023 | The Power of Scrum Mastery: An Analysis of Agile Team Performance and Scrum Master Influence
Hannes Salin, Felix Albrecht, John Skov |
ICSOFT | 1 |
| 2023 | AccA: A Decentralized and Accumulator-Based Authentication and Authorization Architecture for Autonomous IoT in Connected Infrastructures
Hannes Salin |
IoTBDS | 1 |
| 2023 | A Source Hiding Protocol for Cooperative Intelligent Transportation Systems (C-ITS)
Hannes Salin, Lukasz Krzywiecki |
ISPEC | 1 |
| 2023 | A Stochastic Approach Based on Rational Decision-Making for Analyzing Software Engineering Project Status
Hannes Salin |
PROFES (1) | 1 |
| 2023 | Enhancing Tunnel Safety for Dangerous Goods Vehicles through Blockchain-Based Time-StampingabstractIn this study, we explore the potential of integrating blockchain technology and cryptographic primitives such as Schnorr signatures and Pedersen commitments, via a Stamp and Extend scheme, in order to develop a trusted and reliable timestamping system. Our proposed architecture aims to facilitate the safe and reliable platooning of dangerous goods vehicles in C-ITS enabled tunnels. We have implemented a proof-of-concept on the Ethereum platform, demonstrating the feasibility and survivability of our proposed architecture. A series of performance experiments further underscore the potential of our system, reinforcing its value in fostering secure and trusted coordination of dangerous goods transport in connected vehicle tunnels. Karolina Bak, Hannes Salin, Karol Niczyj, Lukasz Krzywiecki |
TrustCom | 2 |
| 2022 | How to Design Authenticated Key Exchange for Wearable Devices: Cryptanalysis of AKE for Health Monitoring and Countermeasures via Distinct SMs with Key Split and Refresh
Lukasz Krzywiecki, Hannes Salin |
CANS | 2 |
| 2022 | Pseudonym Swapping with Secure Accumulators and Double Diffie-Hellman Rounds in Cooperative Intelligent Transport Systems
Hannes Salin |
CRiSIS | 1 |
| 2022 | An Authenticated Accumulator Scheme for Secure Master Key Access in Microservice Architectures
Hannes Salin, Dennis Fokin |
IoTBDS | 1 |
| 2022 | Quality Metrics for Software Development Management and Decision Making: An Analysis of Attitudes and Decisions
Hannes Salin, Yves Rybarczyk, Mengjie Han, Roger G. Nyberg |
PROFES | 1 |
| 2022 | Short Signatures via Multiple Hardware Security Modules with Key Splitting in Circuit Breaking EnvironmentsabstractA Circuit Breaking Environment (CBE) for Connected Railway Infrastructures (CRI) requires that high sensitive cargos are bound to the transportation train carriges. This implies a continous verification of the connectivity and rapid identification of potenital disconnections. For that purpose we consider signatures run on devices with multiple Hardware Security Modules (HSM) architectures. We propose a modification of BLS signatures with an additive key split augumented with a refresh technique. This protects against a powerful adversary that can control distinct HSMs in different signing sessions. Thus, we consider our scheme to be secure even if the adversary switches between chosen HSMs for leakage of partial secrets, from session to session. Finally, we provide promising results from a proof-of- concept implementation, tested on several different type of low- powered devices for comparison. These indicate the feasibility of our constructions. Lukasz Krzywiecki, Hannes Salin |
TrustCom | 2 |
| 2021 | Authenticated Multi-proxy Accumulation Schemes for Delegated Membership Proofs
Hannes Salin, Dennis Fokin, Alexander Johansson |
CRiSIS | 1 |
| 2021 | Multi-Signature Scheme Resistant to Randomness Injection Attacks - A Bitcoin CaseabstractWe propose a modification of a multi-signature scheme, which was previously used as an enhancement of multi-signatures for the Bitcoin cryptocurrency. Our scheme is secure in a new stronger security model in which we allow the forger to inject or control the ephemeral (randomness) values in the end-user's signing device. Thus, our modified scheme is resistant to ephemeral key leakage attacks. We also provide a proof of concept implementation of our scheme, providing a time complexity and performance analysis. Lukasz Krzywiecki, Adam Polubek, Hannes Salin |
NCA | 3 |
| 2021 | Certificateless Multi-Party Authenticated Encryption Mitigating Ephemeral Key LeakageabstractWe propose two secure modifications of a multi-party authenticated encryption scheme with aggregation, mitigating ephemeral leakage attacks on narrowband Internet of Things devices and sensor equipment, used in different type of connected infrastructures. Our schemes are provably secure in a stronger security model where a set of nodes in a 5G-based architecture can produce authenticated and encrypted signcryption messages, aggregated into one verifiable cipher text. We provide benchmarks from a proof of concept implementation, showing the feasibility of our solutions. Lukasz Krzywiecki, Hannes Salin, Mateusz Jachniak |
NCA | 2 |
| 2021 | Cryptanalysis of Deterministic and Probabilistic Multi-Copy PDP Schemes For Cloud Storage - Attacks and CountermeasuresabstractWe provide cryptanalysis of two versions of Provable Data Possession (PDP) constructions. These schemes are proposed for efficient verification of the availability of unmodified data stored in a remote cloud computing platform. We identify problems in the original constructions, as well as the source of errors in the proving methodology. Addressing this, we propose new improved schemes and subsequently, prove their security. To achieve this we reduce the problem of attacking our schemes into breaking the$\top \ell$-assumption, related to the coCDH problem. A benchmark analysis is conducted from proof-of-concept implementations in Python. Bartosz Drzazga, Lukasz Krzywiecki, Hannes Salin |
TrustCom | 3 |
| 2020 | Proxy Signcryption Scheme for Vehicle Infrastructure Immune to Randomness Leakage and Setup AttacksabstractWe propose a proxy signcryption scheme for a multi-party setting, resistant to randomness leakage and setup attacks. Our scheme is an alternative to typical constructions, based on a double Schnorr signature approach, where the linear combination of long term secrets and ephemeral random values occurs both at the initiator and proxy nodes. Our scheme is provably secure in a new stronger model, where the adversary can control the randomness of both parties. Moreover, our proposition is well suited for networks of many independent and moving nodes; especially modern railway infrastructure and vehicle-to-vehicle/infrastructure (V2X) environments, where a broad range of devices with potentially weak computational power and inadequate randomness, is used. Early benchmarks and performance analysis from our proof of concept implementation, suggest that nodes, which use regular Schnorr based schemes, could be successfully upgraded to our more secure alternative construction. Collected timings are still at the acceptable level, proving the applicability of our scheme in modern railway and V2X environments. Lukasz Krzywiecki, Hannes Salin, Nisha Panwar, Mykola Pavlov |
NCA | 2 |